CVE Vulnerabilities

CVE-2024-0410

Published: Feb 22, 2024 | Modified: Mar 04, 2024
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 15.1.0 (including) 16.7.6 (excluding)
Gitlab Gitlab 16.8.0 (including) 16.8.3 (excluding)
Gitlab Gitlab 16.9.0 (including) 16.9.0 (including)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References